CVE Search
Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.
An issue was discovered in GitLab Community and Enterprise Edition 11.9 through 11.11. Unprivileged users were able to access labels, status and merge request counts of confidentia...
An issue was discovered in GitLab Community and Enterprise Edition 11.7 through 11.11. It has Improper Input Validation. Restricted visibility settings allow creating internal proj...
GitLab 10.7 and later through 12.7.2 has Incorrect Access Control.
In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users.
An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure via request smuggling.
GitLab EE 12.2 has Insecure Permissions (issue 2 of 2).
GitLab EE 12.6 and later through 12.7.2 allows Denial of Service.
GitLab EE 11.0 and later through 12.7.2 allows XSS.
GitLab through 12.7.2 allows XSS.
GitLab EE 10.1 through 12.7.2 allows Information Disclosure.
GitLab EE 12.4 and later through 12.7.2 has Incorrect Access Control.
GitLab EE 8.8 and later through 12.7.2 has Insecure Permissions.
GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal.
GitLab EE 8.0 through 12.7.2 has Incorrect Access Control.
GitLab EE 8.0 and later through 12.7.2 allows Information Disclosure.
GitLab EE 8.9 and later through 12.7.2 has Insecure Permission
GitLab EE 8.9 and later through 12.7.2 has Insecure Permission
The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows r...
The (1) create_branch, (2) create_tag, (3) import_project, and (4) fork_project functions in lib/gitlab_projects.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Ente...
An privilege escalation issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 when Mattermost slash commands are used with a blocked account.